|
所在平台: Coursera |
课程主页: https://www.coursera.org/learn/windows-registry-forensics
课程评论:没有评论
课程名称:Windows Registry Forensics(Windows注册表取证) 课程概述:本课程介绍如何检查实时注册表、在取证映像中的注册表文件位置以及如何提取文件。 课程大纲: 1. **Windows注册表简介** - 了解Windows注册表及其在数字取证调查中的重要性,探讨注册表在实时和非实时环境中的位置和结构,以及注册表中的取证证据类型,包括用户帐户信息、系统和用户特定设置、文件访问、程序安装和执行、搜索词、自动启动位置和连接到系统的设备等。 2. **准备检查Windows注册表** - 学习如何设置取证工作站以正确检查Windows注册表,查看Windows操作系统中注册表文件的位置,介绍可用的工具及其使用方法,确保对取证软件进行正确的安装、使用和验证。 3. **NTUser.Dat集文件分析** - 深入分析NTUser.Dat集文件中的取证工件,了解如何定位特定用户的程序和应用、已挂载卷和连接设备、用户搜索词和输入的URL等信息,包括打开和保存的文件、启动时设置运行的程序以及应用程序的安装和执行情况。 4. **SAM集文件** - 解释在SAM(安全帐户管理器)文件中发现的取证工件,学习如何识别本地计算机上的每个用户帐户,并解读用户名信息,包括登录日期、时间和次数。 5. **Software集文件** - 定位与应用程序执行和安装有关的数据,了解软件集文件中的取证工件,包括安装的程序和应用、操作系统类型、安装日期和时间等信息。 6. **System集文件** - 探索系统集文件中具有取证价值的证据,包括当前控制集、计算机名称、最后关机日期和时间等信息,以及与USB设备的连接和断开记录。 7. **USRClass.dat集文件** - 识别并解释UsrClass.dat集文件中的取证工件,学习Windows ShellBags,它用于跟踪用户特定的压缩文件和文件夹访问,包含时间和日期信息,即使是已删除的文件夹。 8. **AmCache集文件** - 检查AmCache集文件,了解与应用程序执行相关的信息,如应用程序安装、首次运行日期和时间、可执行文件的路径以及接入的设备信息。 此课程适合希望深入了解Windows注册表在数字取证中的应用与分析技巧的学生和专业人员。
Name:Introduction to the Windows Registry
Description:Discover what the Windows Registry is and why it is important in digital forensic investigations. This module will explore the location and structure of the registry hives in a live and non-live environment, as well as the types of forensic evidence found in the Windows Registry. This will include: user account information, system-wide and user-specific settings, file access, program installation and execution, search terms, auto-start locations and devices attached to the system. Please use the links and tools provided in the two reading sections to get the URLs and other downloads you will need for the course.
Name:Preparing to Examine the Windows Registry
Description:Learn how to set up a forensic workstation to properly examine the Windows Registry. This module takes a look at the location of the Registry files within the Windows OS and the many tools freely available to view the file structure and artifacts contained within the Windows Registry. It includes instruction on the installation, proper use and validation of your forensic software, showing how to get the most out of your automated tools while maintaining an understanding of what the tool is doing behind the scenes.
Name:NTUser.Dat Hive File Analysis
Description:This module demonstrates an in-depth analysis of the artifacts contained within the NTUser.Dat hive file. This module will show examiners how to locate programs and applications, mounted volumes and connected devices specific to a user, user search terms and typed URLs. Examiners will also be able to locate and identify opened and saved files, typed URLs, user-specific programs set to run at startup and application installation and execution. Examiners will be able to locate, examine and interpret MRU lists (Most Recently Used), UserAssist, user system settings and recently used files.
Name:SAM Hive File
Description:This module explains forensic artifacts found in the SAM (Security Account Manager) file, which stores and organizes information about each user on a system. This module demonstrates how to identify each user account on a local machine using the relative identifier. Examiners can also learn to interpret username information including the users’ login dates, times and login count. The module will show how to identify the machine that the user account was created on, by interpreting a users’ SIDs (machine/domain identifiers) and recovering user password hashes.
Name:Software Hive File
Description:This module will show examiners how to locate information of forensic value relating to application execution and installation contained within the software hive file. The module will provide an overview of the forensic artifacts found in the software hive file, such as installed programs and applications, operating system type, install date and time, wireless network information, file association, domain logon information, the last logged-on user, programs set to run at startup and tracking USB devices that were attached to the system.
Name:System Hive File
Description:This module will demonstrate evidence of forensic value contained within the system hive file. This module explores the system hive file showing how to determine the current control set, computer name, last shutdown date and time, crash dump settings and location, services set to run at startup, page file settings, prefetch settings, last access file time settings, AppCompat Cache, BAM (background activities monitor) and USB device connections and disconnections with dates and times.
Name:USRClass.dat Hive File
Description:This module identifies and explains forensic artifacts found in the UsrClass.dat hive file. This module will look at the UsrClass.dat hive. The examiner will learn to explain Windows ShellBags, which track user-specific zip files and folder access and settings, including dates and times even on deleted folders and removable media. The examiner will also learn to interpret the sub-key MuiCache, to include installed applications. The Microsoft Photo App, showing recently accessed image files, will also be explored.
Name:AmCache Hive File
Description:This module will examine the AmCache hive file, which stores information relating to the execution of applications. A forensic examination of the AmCache hive file showing the following: application installation, application first run date and time, a file path to the executable file, the source of the application, a SHA-1 hash value of the executable file, plug-and-play connected devices, GUIDs of mounted volumes and system hardware information.
The Windows Registry Forensics course shows you how to examine the live registry, the location of the registry files on the forensic image, and how to extract files.